Run the CoolWebShredder, CWShredder.exe, available here:
http://www.spywareinfo.com/~merijn/downloads.html
Have it "fix" identified problems, then check the following entries in the HijackThis Scanlog which may remain, close all browser windows and select "fix checked":
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.portalsearching.com/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.portalsearching.com/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.portalsearching.com/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.portalsearching.com/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.portalsearching.com/search.php?phrase=%s
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL
Many of these browser hijackings are installed through a ByteVerifier hijack, and I would recommend you get the appropriate patches for those, as well as other recent critical updates from Windows update.
http://forums.techguy.org/showthread.php?s=&postid=663486
ByteVerifier:
http://support.microsoft.com/default.aspx?kbid=828026
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-011.asp
http://www.download.windowsupdate.c...l/MSJavWU_8073687b82d41db93f4c2a04af2b34d.exe
The last link is a direct download of the last Virtual Machine. Your current version should be 3810. You can verify that by opening a DOS prompt and entering:
jview
http://www.spywareinfo.com/~merijn/downloads.html
Have it "fix" identified problems, then check the following entries in the HijackThis Scanlog which may remain, close all browser windows and select "fix checked":
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.portalsearching.com/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.portalsearching.com/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.portalsearching.com/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.portalsearching.com/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.portalsearching.com/search.php?phrase=%s
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL
Many of these browser hijackings are installed through a ByteVerifier hijack, and I would recommend you get the appropriate patches for those, as well as other recent critical updates from Windows update.
http://forums.techguy.org/showthread.php?s=&postid=663486
ByteVerifier:
http://support.microsoft.com/default.aspx?kbid=828026
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-011.asp
http://www.download.windowsupdate.c...l/MSJavWU_8073687b82d41db93f4c2a04af2b34d.exe
The last link is a direct download of the last Virtual Machine. Your current version should be 3810. You can verify that by opening a DOS prompt and entering:
jview